Index
Quantum readiness across crypto
Two different questions decide how quantum-exposed crypto is, and they have different answers. First: can the coins themselves be held under a post-quantum signature yet? For every major chain the answer today is no. Second: is the infrastructure that holds and moves those coins, the exchanges and custodians, using post-quantum transport security? That varies, and it is directly measurable. This page tracks both, dated September 2026, with a primary source for every claim.
Can the funds be protected yet?
Whether a chain offers a post-quantum signature for user funds. None do in production. This is why, for the next several years, the only lever holders have is to measure exposure and move at-risk balances, not switch signatures.
| Protocol | PQ signatures for funds | Where it stands |
|---|---|---|
| Bitcoin | Draft | No mainnet quantum-resistant address type. BIP-360 (Pay-to-Merkle-Root) and BIP-361 (legacy signature sunset) are draft soft-fork proposals, not activated. bitcoin/bips: BIP-360 |
| Ethereum | Roadmap | Published post-quantum roadmap; L1 upgrades "could be completed by 2029" per the project. Hash-based leanXMSS is planned for validators; scheme-agile account signatures are a draft (EIP-8202). Nothing live for user accounts. pq.ethereum.org |
| Solana | Experimental | No official protocol-level post-quantum feature. A "Winternitz Vault" using hash-based one-time signatures exists as a third-party, opt-in program, not a shipped Solana change. solana-winternitz-vault (third-party) |
| MPC / threshold-ECDSA custody | None | Splitting a key across parties does not change the signature scheme. The on-chain key and signatures are still ECDSA on secp256k1, which a quantum computer breaks. MPC improves operational security, not quantum resistance. NIST IR 8547 (draft): ECDSA deprecation |
How ready is the infrastructure?
Post-quantum readiness of the public endpoints of major exchanges and custodians, graded by live scan for hybrid ML-KEM key exchange. Each report is reproducible. Note the boundary: a high grade means the venue’s connections resist harvest-now-decrypt-later on its traffic. It says nothing about the coins in custody, which are still secured by classical on-chain signatures like every wallet.
| Grade | Venue | Type | PQ endpoints | |
|---|---|---|---|---|
| A | Binance binance.com | Exchange | 12/12 | report |
| A | Crypto.com crypto.com | Exchange | 12/12 | report |
| A | Kraken kraken.com | Exchange | 4/4 | report |
| A | Robinhood robinhood.com | Exchange | 3/3 | report |
| A | BitGo bitgo.com | Custodian | 5/5 | report |
| A | Ledger ledger.com | Custodian | 2/2 | report |
| B | OKX okx.com | Exchange | 11/12 | report |
| B | Bitfinex bitfinex.com | Exchange | 8/9 | report |
| B | Bybit bybit.com | Exchange | 7/8 | report |
| B | Circle circle.com | Custodian | 6/7 | report |
| B | Coinbase coinbase.com | Exchange | 10/12 | report |
| B | Anchorage anchorage.com | Custodian | 2/3 | report |
| B | Fireblocks fireblocks.com | Custodian | 6/10 | report |
| B | Copper copper.co | Custodian | 2/4 | report |
| C | Gemini gemini.com | Exchange | 5/11 | report |
Grades reflect how many reachable public endpoints negotiate hybrid ML-KEM key exchange. A means every endpoint, B most, C modern TLS but classical key exchange on some or all. This is a September 2026 snapshot; each report is live and re-runs on demand. Method: how these grades are produced.
Timeline context: NIST’s draft IR 8547 sets classical elliptic-curve signatures to be deprecated after 2030 and disallowed after 2035. That deadline lands on the on-chain signatures securing nearly all crypto, not just on web traffic.
Measure a specific holding rather than a venue: paste an address and see the exposed share of its balance, with a signed report.
Measure on-chain exposure